Bernd Prünster

dblp:168/2691 · DBLP profile ↗
← Back
11ranked-venue papers
4as first author
3since 2021 · last 2023
0000-0001-7902-0087ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 9 · 4 first-author · 3 since 2021Systems, architecture and hardware · 1Human-computer interaction and ubiquitous computing · 1Applied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2023 Smoothing the Ride: Providing a Seamless Upgrade Path from Established Cross-Border eID Workflows Towards eID Wallet Systems
Roland Czerny, Christian Kollmann, Blaz Podgorelec, Bernd Prünster, Thomas Zefferer
SECRYPT4
2022 Total Eclipse of the Heart - Disrupting the InterPlanetary File System
Bernd Prünster, Alexander Marsalek, Thomas Zefferer
USENIX Security Symposium1
2021 Armored Twins: Flexible Privacy Protection for Digital Twins through Conditional Proxy Re-Encryption and Multi-Party Computation
Felix Hörandner, Bernd Prünster
SECRYPT2
2020 AndroPRINT: analysing the fingerprintability of the Android API
abstract
In recent Android versions, access to various (unique) identifiers has been restricted or completely removed for third-party applications. However, many information sources can still be combined to create a fingerprint, effectively substituting the need for these unique identifiers. Until now, finding these fingerprintable sources required manually sifting through the API documentation to identify each information source individually. This paper presents AndroPRINT, a framework that automatically recognizes fingerprintable information sources on Android devices. For this purpose it automatically invokes methods, queries fields, and retrieves data from content providers. We show that this framework allows automating the elaborate task of finding such fingerprintable information sources in different experiments. In these experiments, a variety of information sources could be identified, which provide a vast amount of unique features for fingerprinting. Furthermore, AndroPRINT detected undocumented unique device identification features, which are a result of manufacturer adaptations. These vendor customisations even revealed personal data, such as the user's email address and cryptographic keys used for cross-device communication. The fact that this information can be retrieved without the user noticing means that vendor customisations can effectively defeat the tight permission system of modern smartphone operating systems.
Gerald Palfinger, Bernd Prünster
ARES2
2020 Multiply, Divide, and Conquer - Making Fully Decentralised Access Control a Reality
Bernd Prünster, Dominik Ziegler 0001, Gerald Palfinger
NSS1
2020 AndroTIME: Identifying Timing Side Channels in the Android API
abstract
The permission system of Android has continuously evolved to better guard the privacy of users. New permissions have been introduced and existing methods which were abused now require a permission or have been entirely removed. Retrieving private data about users without their consent is thus getting continuously harder for applications. In this paper, we systematically analyse how timing-based side channels in the Android API can be used to circumvent this tight permission system. We introduce AndroTIME, a framework to automatically detect such side channels in the Android API. Using this automated approach, we were able to identify several new timing-based side-channel leaks in Android 10 and Android 11. The detected side channels enable querying for installed applications, active accounts, files, and browser logins. The leaked information could be used to fingerprint users, detect secret user habits, or even infer a concrete user identity.
Gerald Palfinger, Bernd Prünster, Dominik Ziegler 0001
TrustCom2
2019 Phish-Hook: Detecting Phishing Certificates Using Certificate Transparency Logs
Edona Fasllija, Hasan Ferit Eniser, Bernd Prünster
SecureComm (2)3
2018 A Holistic Approach Towards Peer-to-Peer Security and Why Proof of Work Won't Do
Bernd Prünster, Dominik Ziegler 0001, Christian Kollmann, Bojan Suzic
SecureComm (2)1
2017 Hybrid Mobile Edge Computing: Unleashing the Full Potential of Edge Computing in Mobile Device Use Cases
abstract
Many different technologies fostering and supporting distributed and decentralized computing scenarios emerged recently. Edge computing provides the necessary on-demand computing power for Internet-of-Things (IoT) devices where it is needed. Computing power is moved closer to the consumer, with the effect of reducing latency and increasing fail-safety due to absent centralized structures. This is an enabler for applications requiring high-bandwidth uplinks and low latencies to computing units. In this paper, a new use case for edge computing is identified. Mobile devices can overcome their battery limitations and performance constraints by dynamically using the edge-computing-provided computational power. We call this new technology Hybrid Mobile Edge Computing. We present a general architecture and framework, which targets the mobile device use case of hybrid mobile edge computing, not only considering the improvement of performance and energy consumption, but also providing means to protect user privacy, sensitive data and computations. The achieved results are backed by the results of our analysis, targeting the energy saving potentials and possible performance improvements.
Andreas Reiter, Bernd Prünster, Thomas Zefferer
CCGrid2
2017 The Net Rat - Rethinking Connected Services for Increased Security
Bernd Prünster, Florian Reimair, Andreas Reiter
SECRYPT1
2015 Applying the Formal Concept Analysis to Introduce Guidance in an Inquiry-Based Learning Environment
abstract
The European research project weSPOT aims at supporting science learning in secondary and higher education. The underlying pedagogical approach, inquiry-based learning, is often criticized for the lack in teaching learning content and for overburden novice learners. To fill this gap, we developed the Formal Concept Analysis (FCA) tool which is used by teachers to define a knowledge domain, i.e. The objects, attributes and their relations to each other. Learning resources can be assigned to subsets of objects and attributes. By navigating through the concept lattice students get an overview of the topic. They learn by consuming learning resources, either in a self-regulated way, by interacting with the nodes of the lattice, or when following a recommender system which suggests learning resources based on the domain model and defined pedagogical rules. The paper describes the FCA tool and how it is used by teachers and students, and the recommendation strategy that supports students when browsing the knowledge domain.
Michael A. Bedek, Simone Kopeinik, Bernd Prünster, Dietrich Albert
ICALT3